On the afternoon of September 24, 2026, Bitget’s monitoring systems flagged unauthorized activity originating from several of its online wallets. Within roughly sixty minutes, assets valued at about $183 million left addresses linked to the exchange and were consolidated into a brand-new address. Subsequent analysis showed that the total outflow from the exchange’s hot wallets exceeded $350 million, encompassing Ethereum, stablecoins, Avalanche, Binance Coin, and other tokens.

How the funds were moved

The first notable transaction involved a fresh wallet that received approximately $19.67 million worth of a cross-chain stablecoin version of Tether. That balance was instantly exchanged for 7,111 Ethereum on the Arbitrum layer-2 network, a swap that completed in six minutes. The trade was executed through decentralized aggregators that allow direct on-chain swaps, with the buyer paying roughly five percent above the prevailing market price—an indication that speed was prioritized over cost. After this initial move, additional wallets associated with Bitget transferred holdings of Ether, Avalanche, Binance Coin, USDC, USDT and a gold-backed token to the same destination address. Activity tapered off about six minutes after the first trade, suggesting the exchange began blocking withdrawals while investigating.

Exchange response and user protection

Bitget’s chief executive, Gracy Chen, confirmed the incident on the platform’s official channel, emphasizing that the exchange’s offline, or cold, wallets remain untouched. She reassured customers that the entire loss falls inside the scope of the company’s User Protection Fund, which now contains more than $464 million. The fund, originally announced in 2023 with a $300 million allocation, is designed to reimburse users in the event of hacks, thefts or similar incidents. Chen added that the compromised wallets were the hot wallets used for daily transaction processing, not the offline reserves that store the bulk of client assets.

Industry context

The Bitget breach follows a series of high-profile exchange attacks in recent years. In early 2025, a rival platform suffered a $1.4 billion loss after attackers spoofed a signing interface to divert a cold-wallet transfer. Across the broader market, hackers extracted roughly $2.72 billion from exchanges and protocols in the previous year. These events highlight the persistent risk associated with centralized custodial services, where the “not your keys, not your coins” principle often fails to protect users.

Why it matters

The incident underscores the vulnerability of hot-wallet infrastructure, which is essential for providing quick withdrawal services but remains an attractive target for cyber-criminals. Bitget’s reliance on a sizable protection fund offers a safety net for users, yet it also raises questions about the long-term sustainability of such insurance models in a landscape where attackers continuously refine their tactics. For traders and investors, the breach serves as a reminder to evaluate custodial risk and consider diversifying storage strategies.